Reports for Every Cloud

Purpose-built reports that answer the questions cloud and security teams actually ask — across AWS, Azure, and Google Cloud.

58
Curated Reports
1705+
Controls Checked
3
Cloud Providers
5 min
To First Results
ASecureCloud report preview
Azure logo

Identity & Access Management

37 controls
13 services covered

Reviews direct identity and authorization controls, including Entra tenant settings, MFA, guest access, user consent, managed identity, Azure AD authentication, RBAC, local-auth disablement, and shared-key restrictions.

What we check

Entra Tenant Identity9
  • Security Defaults are Enabled on Azure Active Directory
  • Ensure self-service password reset is enabled
  • Enable Conditional Access policies to block legacy authentication
  • Admin Consent Workflow is Enabled
  • Ensure 'Microsoft Azure Management' is limited to administrative roles
  • Ensure Sign-in frequency is enabled and browser sessions are not persistent for Administrative users
  • Enable Azure AD Identity Protection sign-in risk policies
  • AD Account Provisioning Activity Report Reviewed
  • Ensure the Azure AD 'Risky sign-ins' report is reviewed at least weekly
Guests and External Users6
  • Ensure Guest Users are reviewed at least biweekly
  • Ensure Guest Users are Reviewed Monthly
  • Ensure Guest Invite Restrictions are Restricted
  • Ensure Guest User Access Restrictions are Restricted
  • Guest accounts with read permissions on Azure resources should be removed
  • Guest accounts with write permissions on Azure resources should be removed
Entra MFA4
  • Admin Users have MFA Enabled
  • All Users have MFA Enabled
  • Ensure Conditional Access MFA is Enabled
  • Ensure MFA is Required for Device Join
User Consent and Groups4
  • Ensure User Consent for Applications is Disabled
  • Ensure User Consent is Limited to Verified Publishers and Selected Permissions
  • Ensure Microsoft 365 Group Creation is Disabled
  • Ensure third party integrated applications are not allowed
Event Grid Identity and Local Auth3
  • EventGrid Domains Use Managed Identity
  • EventGrid Topics Use Managed Identity
  • EventGrid Topics Do Not Use Local Authentication
Managed Identity2
  • Web Apps Should Use Managed Identity
  • Function Apps Should Use Managed Identity
Storage Identity Authorization2
  • Default to Microsoft Entra Authorization Should Be Enabled for Storage Accounts
  • Shared Key Access Should Be Disabled for Storage Accounts
Cosmos DB Identity Authorization2
  • Cosmos DB account 'Access Control' should be configured to use Azure Active Directory (AAD) and Role-Based Access Control (RBAC)
  • CosmosDB Account Should Disable Key Based Metadata Write Access
Service Authentication1
  • Service Bus Namespace should be configured with Azure Active Directory authentication
Search Identity1
  • Search Services Use Managed Identity
Batch Identity1
  • Batch Accounts Identity Provider Should Be Enabled
Container Instance Identity1
  • Container Instance Container Groups Use Managed Identity
Cognitive Services Identity1
  • Cognitive Services Accounts should have Local Authentication Methods Disabled

Run these reports on your own cloud

Connect an account and get your first set of reports in minutes — free to start, no credit card required.